CVE-2023-49061
- EPSS 0.31%
- Veröffentlicht 21.11.2023 15:15:07
- Zuletzt bearbeitet 19.08.2026 15:30:33
An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.
CVE-2023-49060
- EPSS 0.64%
- Veröffentlicht 21.11.2023 15:15:07
- Zuletzt bearbeitet 19.08.2026 15:30:33
An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulnerability affects Firefox for iOS < 120.
CVE-2023-5758
- EPSS 0.43%
- Veröffentlicht 25.10.2023 18:17:45
- Zuletzt bearbeitet 19.08.2026 15:30:33
When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS) attack. This vulnerability affects Firefox for iOS < 119.
CVE-2023-29546
- EPSS 0.49%
- Veröffentlicht 19.06.2023 11:15:09
- Zuletzt bearbeitet 19.08.2026 15:29:21
When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information. *This bug only affects Firefox for Android. Other operating systems are unaffected.*...
CVE-2023-29534
- EPSS 0.7%
- Veröffentlicht 19.06.2023 11:15:09
- Zuletzt bearbeitet 19.08.2026 15:29:21
Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Fir...
CVE-2023-25747
- EPSS 0.6%
- Veröffentlicht 19.06.2023 11:15:09
- Zuletzt bearbeitet 19.08.2026 15:29:21
A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox f...
CVE-2023-29551
- EPSS 0.52%
- Veröffentlicht 02.06.2023 17:15:13
- Zuletzt bearbeitet 19.08.2026 15:29:21
Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox for Android < ...
CVE-2023-29543
- EPSS 0.52%
- Veröffentlicht 02.06.2023 17:15:12
- Zuletzt bearbeitet 19.08.2026 15:29:21
An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
CVE-2023-29533
- EPSS 0.56%
- Veröffentlicht 02.06.2023 17:15:12
- Zuletzt bearbeitet 19.08.2026 15:29:21
A website could have obscured the fullscreen notification by using a combination of <code>window.open</code>, fullscreen requests, <code>window.name</code> assignments, and <code>setInterval</code> calls. This could have led to user confusion and pos...
CVE-2023-29535
- EPSS 0.74%
- Veröffentlicht 02.06.2023 17:15:12
- Zuletzt bearbeitet 19.08.2026 15:29:21
Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, F...